About
Arbaz Khan
Cybersecurity & Systems Engineer
My day job puts me in the middle of a live network, managing endpoints, configuring servers, and keeping business-critical services running under real operational pressure. That environment taught me something quickly: maintaining a system and securing it are two very different problems.
That gap is what pulled me toward cybersecurity. I started looking at the infrastructure I managed through an attacker's perspective, not to find blame, but to find gaps before someone else did. Structured vulnerability testing became part of how I think, and when I find a flaw, patching it isn't enough. I want to know how it works. That curiosity is what led me into malware analysis: tracing how a payload executes, how it touches the registry, how it slips past standard detection.
Those findings feed directly back into how I build defensive systems, deploying Suricata for network-level visibility, using BitDefender EDR for endpoint behavior, and centralizing logs in Wazuh and Zabbix so nothing goes unnoticed. All of it runs within the ISO/IEC 27001 framework, because security work without documented process is just reactive chaos.
Currently learning / building
Cloud security architecture and detection engineering
Experience
-
IT Support Executive
· Sapphire Consulting Services · Karachi, Pakistan
Oct 2025 – Present
Administering endpoint security via BitDefender GravityZone EDR across a multi-site enterprise deployment. Managing infrastructure monitoring with Zabbix, Grafana, and Prometheus. Handling backup and disaster recovery operations using Veeam. Providing L1–L2 technical support and incident resolution across multiple client sites.
-
Information Security Associate
· SignDevOps · Remote (Florida, USA)
Sep 2024 – May 2025
Conducted web application and network penetration testing for client infrastructure using Nmap, Nikto, and Burp Suite Enterprise Edition. Performed exploitation testing with Metasploit Framework and vulnerability scanning with Tenable Nessus. Authored detailed penetration testing reports with findings, risk ratings, and remediation recommendations aligned to OWASP Top 10.
Certificates
- ISO/IEC 27001:2022 Information Security Associate — SkillFront, 2026 Verify
- Certified Ethical Hacking (CEH) - Training Completion — Corvit Systems, 2026 File
- Google IT Support Professional Certificate (v2) — Coursera, 2025 Verify
Skills